Leveraging context enrichment
Ingesting threat artifacts as part of the informed defense strategy is usually not the only step required for security tools. Many tools require additional use cases created to make use of the threat artifacts indexed within the tool. We saw a glimpse of this in Lab 2.3, where an additional ruleset was needed within the Wazuh configuration. To further bolster our threat artifacts as actual enrichment, we need to pair the intelligence with practical use cases.
The most common use cases are SIEM based, which can compare the ingested IOCs and IOAs against TTPs and may include the following:
- Command and Control (C2) heartbeats
- Data exfiltration
- Chained process executions
In addition to the standard use case detections, some SIEMs support risk-based rulesets, which allow for certain objects, such as users, system hostnames, and other key fields, to increase their risk thresholds based on changing conditions as a way to leverage the...